How to Set Up Email Authentication in Zoho CRM

Email Authentication in Zoho CRM

Email Authentication lets you send emails from Zoho CRM using your own domain, in a way that other mail servers trust rather than flag as suspicious.

Important: If your domain isn't authenticated, Zoho CRM will not let you send from your own email addresses. Instead, outgoing emails are automatically replaced with one of Zoho's own authenticated domains. If you want emails to genuinely appear as coming from your business, authenticating your domain isn't optional.

What needs to be set up

  • Domain Verification. Confirms you actually own the domain you want to send from. Mandatory.
  • DKIM (DomainKeys Identified Mail). Uses public key encryption to confirm a message hasn't been altered in transit. Mandatory, and required for good email deliverability.
  • SPF (Sender Policy Framework). Defines which servers are allowed to send email on behalf of your domain. Recommended rather than mandatory, but adds meaningful protection against your domain being spoofed and helps prevent your emails being marked as spam.

How to add and authenticate your domain

  1. Open Email Authentication. Go to Setup, then Channels, then Email, then Email Deliverability, then Email Authentication.
  2. Add your domain. Click Add Domain and follow the prompts to verify ownership, typically by confirming a code sent to an email address on that domain.
  3. Validate your records. Once verified, click Validate Records to see the exact DKIM and SPF values Zoho CRM needs.
  4. Publish the DNS records. Add the DKIM TXT record, and the SPF include if you're setting that up too, in your domain's DNS settings via your domain registrar or DNS provider.
  5. Validate in Zoho CRM. Once the DNS change has propagated, which can take anywhere from a few minutes to 48 hours, return to Zoho CRM and validate the record again to confirm it's picked up correctly.
Note on SPF alignment: Zoho CRM sends using its own domain as the technical "envelope from" address, which is separate from the "from" address your recipients see. Because of this, SPF alignment checks under DMARC can still fail even after SPF is set up correctly, since SPF checks the envelope domain rather than the visible sender domain. DKIM doesn't have this limitation and is generally the more reliable path to DMARC alignment for CRM-sent email, which is part of why it's mandatory rather than just recommended.
Need help? 1 Cloud Consultants can help you set up DKIM and SPF correctly for Zoho CRM, and troubleshoot DMARC alignment issues affecting your email deliverability. Book a discovery call with 1 Cloud Consultants.